CVE-2025-37826: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer() Add a NULL check for the returned hwq pointer by ufshcd_mcq_req_to_hwq(). This is similar to the fix in commit 74736103fb41 ("scsi: ufs: core: Fix ufshcd_abort_one racing issue").

Affected products

  • Linux Linux Kernel: from 6.5, before 6.12.26 (fixed in 6.12.26); from 6.13, before 6.14.5 (fixed in 6.14.5); version 6.15 only

Published 2025-05-08. Last modified 2026-06-17.